minetest-mod-advtrains-git
The package clones source code from the project's own git repository on a non-whitelisted but plausibly official host; building from source is normal for AUR packages, and no unverifiable prebuilt binaries are executed.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package clones source code from the project's own git repository on a non-whitelisted but plausibly official host; building from source is normal for AUR packages, and no unverifiable prebuilt binaries are executed.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:19
source=("$_gitname::git+https://git.bananach.space/advtrains.git"
PKGBUILD
1 offending line(s) highlighted# Maintainer: ywang <ywang@forksworld.de>
# Preivous maintainer: shellkr <revoltism+AUR$gmail.com>
pkgname=minetest-mod-advtrains-git
_gitname=${pkgname%-git*}
_basic_trains=minetest-mod-basic_trains
pkgver=814.43c85ab.b43.61a4526
pkgrel=1
epoch=1
pkgdesc='This mod adds good-looking, realistic trains to minetest. It also introduces rails that make turns of only 30 degrees instead of 90. (Mod for Minetest)'
arch=('any')
url="https://git.bananach.space/advtrains"
license=('custom')
depends=()
optdepends=('minetest-usrdir_patch')
makedepends=('git')
provides=("$_gitname" "$_basic_trains")
install=$pkgname.install
source=("$_gitname::git+https://git.bananach.space/advtrains.git"
"$_basic_trains::git+https://git.bananach.space/basic_trains.git")
md5sums=('SKIP' 'SKIP')
pkgver() {
cd "$srcdir/$_gitname"
echo $(git rev-list --count master).$(git rev-parse --short master).b$(git -C "$srcdir/$_basic_trains" rev-list --count master).$(git -C "$srcdir/$_basic_trains" rev-parse --short master)
}
package() {
cd "$srcdir/$_gitname"
mkdir -p "$pkgdir/usr/share/minetest/mods/${_gitname#*mod-}"
cp -r * "$pkgdir/usr/share/minetest/mods/${_gitname#*mod-}"
cd "$pkgdir/usr/share/minetest/mods/${_gitname#*mod-}"
rm -rf assets
mkdir -p "$pkgdir/usr/share/doc/${_gitname}"
mv */doc/* "../../../doc/${_gitname}/"
cd "$srcdir/$_basic_trains"
mkdir -p "$pkgdir/usr/share/minetest/mods/${_basic_trains#*mod-}"
cp -r * "$pkgdir/usr/share/minetest/mods/${_basic_trains#*mod-}"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |